CVE-2024-42718: Croogo

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.

Affected products

  • Croogo Croogo: version 4.0.7 only

Published 2025-12-26. Last modified 2026-06-17.